Crun: crun: /dev/console symlink follow allows root-owned file creation outside the rootfs
Published Sep 10, 2026
5.6
MEDIUMCVSS 3.1
EPSS 0.12%
Description
A flaw was found in crun. When the container configuration does not give /dev a dedicated mount, terminal setup can redirect /dev/console onto an attacker-controlled path, including via the read-only-rootfs bind-mount fallback. Affected versions are crun 1.29.1 and earlier. Default configurations that mount a fresh /dev are not exposed. No fixed release is available yet.
Affected products
-
-
-
-
-
- Version 0StatusaffectedConstraints<=1.29.1
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 | affected |
| ||||||
| Red Hat | Red Hat Enterprise Linux 8 | affected |
| ||||||
| Red Hat | Red Hat Enterprise Linux 9 | affected |
| ||||||
| Red Hat | Red Hat OpenShift Container Platform 4 | affected |
| ||||||
| Containers | Crun | unaffected |
|
No data.
No data.
Red Hat Enterprise Linux 10
crun
Fix deferred
Red Hat Enterprise Linux 8
container-tools:rhel8/crun
Fix deferred
Red Hat Enterprise Linux 9
crun
Fix deferred
Red Hat Hardened Images
crun
Affected
Red Hat OpenShift Container Platform 4
crun
Fix deferred
Red Hat OpenShift Container Platform 4
openshift/ose-rhel-coreos-8
Fix deferred
Red Hat OpenShift Container Platform 4
openshift/ose-rhel-coreos-9
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | crun | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | container-tools:rhel8/crun | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | crun | Fix deferred | n/a |
| Red Hat Hardened Images | crun | Affected | n/a |
| Red Hat OpenShift Container Platform 4 | crun | Fix deferred | n/a |
| Red Hat OpenShift Container Platform 4 | openshift/ose-rhel-coreos-8 | Fix deferred | n/a |
| Red Hat OpenShift Container Platform 4 | openshift/ose-rhel-coreos-9 | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
Vendor solution
Always mount /dev (Podman/crun default). Do not run untrusted images with a /dev-less config.
Red Hat statement
Exploitation requires an OCI configuration that does not mount /dev, plus a malicious image. Supported Red Hat container tooling mounts /dev by default. Red Hat products are not affected in supported configurations.
Red Hat mitigation
Always mount /dev (Podman/crun default). Do not run untrusted images with a /dev-less config.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:H/A:N
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
PartialDecision
n/aAssessed Sep 10, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 3, 2026.
Score over time
Sep–Oct 2026- EPSS v5
Percentile over time
- EPSS v5
Table of values (2 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 3, 2026 | 0.12% (0.00121) | 1.71th | v5 (v2026.06.15) |
| Sep 10, 2026 | 0.12% (0.00117) | 1.88th | v5 (v2026.06.15) |
References (6)
- https://access.redhat.com/errata/RHSA-2026:71668 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2026-88264 vdb-entryx_refsource_REDHATVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2531223 issue-trackingx_refsource_REDHATIssue Tracking
- https://github.com/containers/crun/
- https://nvd.nist.gov/vuln/detail/CVE-2026-88264
- https://www.cve.org/CVERecord?id=CVE-2026-88264
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/errata/RHSA-2026:71668 | vendor-advisoryx_refsource_REDHAT | |
| https://access.redhat.com/security/cve/CVE-2026-88264 | vdb-entryx_refsource_REDHATVendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2531223 | issue-trackingx_refsource_REDHATIssue Tracking | |
| https://github.com/containers/crun/ | ||
| https://nvd.nist.gov/vuln/detail/CVE-2026-88264 | ||
| https://www.cve.org/CVERecord?id=CVE-2026-88264 |
Change history (0)
No recorded changes yet.